Shunrong Jiang

dblp:132/7878 · also ShunRong Jiang · DBLP profile ↗
← Back
45ranked-venue papers
25as first author
23since 2021 · last 2026
0000-0003-2823-1794ORCID · verified

Domains — the database's venue-derived domains; a paper can count in several

Computer networks · 31 · 16 first-author · 14 since 2021Security and privacy · 5 · 2 first-author · 4 since 2021Applied, interdisciplinary, general and emerging computing · 4 · 3 first-author · 2 since 2021Software engineering, systems software and programming languages · 3 · 3 first-author · 2 since 2021Systems, architecture and hardware · 2 · 1 first-author · 1 since 2021
YearPublicationVenuePosition
2026 BFCrowd: Federated Crowdsourcing With Privacy-Aware and Fine-Grained Task Matching via Blockchain
abstract
Nowadays, crowdsourcing has evolved into a cost-efficient and scalable task execution paradigm that benefits both task requesters and workers. Task matching is a crucial crowdsourcing procedure for deciding the task execution quality, but security and privacy concerns arise as the crowdsourcing platform cannot be fully trusted. Existing privacy-aware task-matching schemes are limited to intra-platform central matching in the semi-honest model and coarse-grained keyword/location-based matching over one single attribute. Solutions supporting secure cross-platform and fine-grained task matching in the malicious model are urgently needed. In this paper, we first formally defined BFCrowd, a federated crowdsourcing system built on a consortium blockchain. BFCrowd aggregates multi-platform resources and enables decentralized and reliable cross-platform task matching using smart contracts, in the presence of malicious workers and platforms. Notably, we design a fully secure ciphertext-policy attribute-based encryption scheme with concealed access policies and user-side lightweight decryption, which thoroughly caters to the dual-side privacy demand and resource-limited workers and serves for fine-grained expressive task matching over multiple attributes. Moreover, it supports comparison over numerical attributes. Formal security analysis proves the desirable privacy guarantees in the standard model and collusion resistance. Extensive experiments implemented atop Hyperledger Fabric demonstrate both on-chain and off-chain performance.
Haiqin Wu, Boris Düdder, Zihan Wu 0003, Shunrong Jiang, Liangmin Wang 0001
IEEE Trans. Dependable Secur. Comput.4
2025 Blockchain-Enabled EHR Sharing Framework with Dual-Protection: Integrating Attribute-Based Encryption and Hierarchical Role Access Control
abstract
The global healthcare landscape has witnessed accelerated adoption of digital transformation initiatives, with electronic health records (EHRs) emerging as the cornerstone technology for modern medical data management. While EHR systems effectively consolidate patient information and improve clinical continuity, their predominant centralised architectures create data silos that impede cross-institutional interoperability and patient sovereignty over personal health data. In this paper, we propose a blockchain-enabled EHR sharing framework that integrates attribute-based encryption with hierarchical role-based access control (RBAC) mechanisms. Our dual-protection architecture combines 1) an attribute-oriented privacy preservation scheme that ensures data immutability and fine-grained access through cryptographic proofs, with 2) a multi-level role hierarchy system that enables efficient permission management among healthcare stakeholders. By establishing dynamic mappings between user attributes and institutional roles, we achieve secure yet flexible authorization processes without compromising system performance. Experimental evaluations demonstrate superior performance metrics in cryptographic operations and access verification latency, validating the practicality of the framework for real-world EHR exchange scenarios.
Shunrong Jiang, Chengcheng Zhang 0003, YuQi Zhang, Haotian Chi, Xiaojiang Du
GLOBECOM1
2025 FedU-KAN: Cloud-Enhanced Privacy-Preserving Federated Learning for Medical Image Segmentation Based on U-KAN
abstract
Machine learning is gradually transforming medical image segmentation. However, its accuracy often relies on large-scale medical datasets, while centralized data collection raises serious privacy concerns. To address this issue, federated learning (FL) enables collaborative model training without sharing raw data, thus effectively protecting patient privacy. Despite this advantage, commonly used segmentation models, such as U-Net and its variants, typically have large parameter sizes, making them inefficient for local training on FL clients. To overcome this challenge, we propose FedU-KAN, a framework built upon the lightweight U-KAN architecture, tailored for federated medical image segmentation tasks. Moreover, we design an adaptive differential privacy mechanism that dynamically adjusts gradient clipping based on feature importance. This approach helps preserve anatomical details while reducing the risk of privacy leakage. We evaluate FedU-KAN on the CVC-ClinicDB and Kvasir-SEG datasets, where it achieves IoU scores of 87.09% and 83.38%, respectively—outperforming standard FL baselines. These results demonstrate that FedU-KAN can effectively balance privacy protection and model performance in real-world medical segmentation scenarios.
Haotian Chi, Shunrong Jiang, Xiaojiang Du, Nadjib Aitsaadi
GLOBECOM5
2025 Smart Contract Vulnerability Detection via Heterogeneous Graph Representation and Dual Attention Mechanisms
Yingying Qu, Jiangtao Cui, Haotian Chi, Haijun Geng, Shunrong Jiang, Xiaojiang Du
GLOBECOM5
2025 Privacy-Preserving Distributed Optimization Scheme for Battery Swapping and Charging System With Homomorphic Encryption to Protect Wireless Communications
abstract
The proliferation of electric vehicles (EVs) has spurred a growing demand for efficient battery exchange and charging services, making the battery swapping-charging system (BSCS) an attractive solution.The various subsystems of the BSCS exchange data in real-time through wireless communication. However, due to the openness of wireless communication, data can be easily intercepted and tampered with during transmission, which may lead to the leakage of sensitive information. To address this, we introduce a privacy-preserving distributed optimization algorithm, leveraging homomorphic encryption and multi-party secure computing in the BSCS context. Initially, we formulate the operation management problem of BSCS problem as a constrained mixed integer programming (MIP) and employ the alternating direction method of multipliers (ADMM) for optimal resolution. Subsequently, we integrate ADMM with the Paillier cryptosystem for privacy protection. Empirical validation substantiates the algorithm security and convergence, ensuring that adversaries cannot deduce private information. Notably, the proposed algorithm yields a solution closely resembling the centralized solution, with a superior convergence rate compared to alternative methods.
Zhuocheng Sun, Haotian Chi, Shunrong Jiang, Xiaojiang Du, Nadjib Aitsaadi
GLOBECOM4
2025 Effective Dual-Layer Poison Attacks Detection in Privacy-preserving Federated Learning
abstract
Although federated learning offers a certain degree of privacy by aggregating user gradients instead of raw data, it remains vulnerable to various attacks, such as model poisoning. Existing defense mechanisms often address poisoning threats at the cost of exposing gradient information, which can lead to privacy risks such as member inference attacks. While techniques like cryptography or differential privacy can be employed to mitigate these risks, they often come with significant efficiency trade-offs. At the same time, a non-IID heterogeneous environment is also a big challenge. To address these challenges holistically, this paper proposes a dual-layer detection scheme (EDDFL). It combines norm-based filtering and isolation forest detection to effectively filter out malicious gradients, thereby preserving model accuracy even in adversarial environments. Furthermore, we incorporate a gradient quantization method that not only protects gradient privacy but also improves communication efficiency. Compared with existing approaches, the proposed method effectively addresses the challenges of model poisoning, gradient leakage, and data heterogeneity under non-IID settings. Experimental results demonstrate that our scheme significantly reduces both computational and communication overhead while maintaining privacy guarantees.
Xiao Zhang 0047, Haotian Chi, Shunrong Jiang, Xiaojiang Du, Danny Hughes 0001
GLOBECOM4
2025 MHTGR: Multi-Modal Hierarchical Temporal Graph Representation Learning for Ethereum Phishing Detection
abstract
Ethereum's swift development has elevated phishing scams to primary security concerns within blockchain networks. Current detection methods face three key challenges: insufficient hierarchical temporal modeling, inadequate pattern-aware structural recognition, and the lack of effective mechanisms to integrate multi-modal information. This paper presents an innovative approach for phishing detection using Multi-modal Hierarchical Temporal Graph Representation (MHTGR). Our method analyzes phishing behaviors by jointly considering temporal dynamics and structural topology of transaction data. First, we construct Hierarchical Transaction Graph Network (HTGN) to organize raw transaction records into structured graph representations. Then, multiple feature modalities are extracted through a Parallel Feature Extraction (PFE) module. Finally, these features are integrated via a Multi-modal Fusion (MMF) module for comprehensive phishing detection. Empirical evaluations conducted across multiple datasets from Ethereum demonstrate that the proposed method outperforms existing methods, providing effective solutions towards blockchain security.
Shunrong Jiang, Yong Zhou 0003
ICPADS2
2025 Hybrid Makes Better: Hybrid Differential Privacy Medical Image Classification Based on Federated Learning
abstract
Machine learning has the potential to revolutionize medical image classification. However, machine learning requires large medical datasets to improve accuracy, which will compromise patient privacy. Federated learning is a promising technique that protects patient privacy and improves the accuracy of medical image classification. Unfortunately, current research shows that federated learning faces the risk of privacy leakage. In this paper, we propose a privacy-preserving federal learning scheme via hybrid differential privacy for medical image classification (FHDM). Specifically, we construct a local hybrid differential privacy algorithm (LHDP) against patients' privacy leakage. This hybrid algorithm combines Gaussian and Laplace differential privacy without enlarging the privacy budget. We prove that the algorithm applies to the model parameter. Moreover, we design loss optimization and global optimization strategies on the algorithm to achieve higher accuracy in medical image classification. Finally, we validate FHDM in terms of privacy-preserving and model accuracy on real datasets. Experiments show that FHDM effectively protects privacy and improves the average accuracy by 9.60% compared to previous differential privacy schemes with the same medical image dataset and privacy budget.
Shunrong Jiang, Haotian Chi, Xiaojiang Du
IEEE Trans. Dependable Secur. Comput.1
2025 ECAKM: Efficient Conditional Anonymous Authentication Scheme With On-Chain Key Management in VANETs
abstract
Conditional anonymous authentication can provide anonymity and traceability to Vehicular Ad-Hoc Networks (VANETs), which protects users’ privacy while resisting malicious users and false messages. However, existing schemes suffer from various disadvantages, such as unavailable batch verification, unrenewable user public keys/certificates, and untimely revocation. In this paper, we propose an efficient conditional anonymous authentication scheme with on-chain key management (ECAKM) in VANETs. To achieve lightweight authentication, we design an efficient Signature of Knowledge (SoK) and a batch verification algorithm. We also employ a Bloom filter on the chain to manage the information about revoked anonymous public keys to further improve the efficiency of our scheme. Moreover, we adopt hash chain technology to update users’ anonymous public keys and protect vehicles against linkage attacks. In addition, based on the blockchain and smart contract (SC), we can manage anonymous public keys of users efficiently and transparently. Security analysis and experimental results demonstrate that our scheme ensures conditional privacy with a reduced authentication overhead.
Shunrong Jiang, Xiao Zhang 0047, Guohuai Sang, Haotian Chi, Yong Zhou 0003
IEEE Trans. Intell. Transp. Syst.1
2025 ARMM: Sandwich-Attack Resilient Automated Market Maker
Shunrong Jiang
IEEE Trans. Serv. Comput.1
2024 Isolate and Detect the Untrusted Driver with a Virtual Box
abstract
In kernel, the driver code is much more than the core code, thus having a larger attack surface. Especially for the untrusted drivers without source code, they may come from the hot-plug hardware or the user without security knowledge. Traditional isolation methods require analyzing source code to set checkpoints in the driver for control flow protection, which are not available for closed-source drivers. Evenworse, the existing isolation methods can only prevent the hijacked control flows entering/existing drivers, while they cannot discover the illegal control flows inside drivers. Although the kernel address space location randomization (KASLR) can defend against control flow hijacking, it can be bypassed by code probes. In response to these issues, this paper proposes a novel method Dbox to isolate and detect the untrusted drivers whose source code is unavailable. Dbox creates a light hypervisor to monitor and analyze the untrusted driver's behavior without relying on source code. It isolates the untrusted driver in a private space and dynamically changes its virtual space through a sliding space mechanism. Under the protection of Dbox, all control flows jumping to/from untrusted drivers can be detected. Experiments and analysis show that Dbox has good protection against code probes, kernel rootkits and code reuse attacks, and the overhead introduced to the operating system is less than 3.6% in general scenarios.
Shunrong Jiang, Yong Zhou 0003, Yeh-Ching Chung
CCS2
2024 DPFedSAM-Meas: Comparison Of Differential Privacy Federated Learning In Medical Image Classification
abstract
Machine learning is widely used in medical image classification tasks. However, medical images often exhibit uneven distribution and high sensitivity to noise. A feasible solution involves using federated learning (FL) with differential privacy (DP), a distributed training method that protects patient privacy. In this work, many studies have proposed improved solutions for localized differential-private federated learning (DP-FL) frameworks. However, these studies are isolated, which would be detrimental to privacy practitioners in designing and using the algorithms. To provide a comprehensive analysis of these algorithms, we propose DPFedSAM-Meas, as a framework for comprehensive utility analysis of DP-FL. In this framework, we employed the state-of-the-art federated learning framework FedSAM. Moreover, we categorize DP algorithms into Laplace DP and Gaussian DP by the underlying DP mechanisms, and into Gradient DP and Parameter DP by the DP position in FL train. DPFedSAM-Meas allows a comparative analysis of these four DP techniques, measuring their model utility, privacy leakage, and overhead when FL uses different network structures. Finally, we evaluate DPFedSAM-Meas on datasets of Pneumonia, Blood, and Path, aiming to investigate the performance of different DP techniques on mainstream deep learning algorithms, including Convolutional Neural Networks (CNN) and Vision Transformers (ViT).
Shunrong Jiang, Haotian Chi, Xiaojiang Du
GLOBECOM1
2024 Hybrid Makes Better: Privacy-Preserving Medical Image Classification Based on Federated Learning
abstract
The power of machine learning makes it available for medical image classification. However, machine learning requires large medical datasets to improve accuracy, which will involve patients’ private information and lead to their privacy leakage. Federated learning is a trending technique to both protect patients’ privacy and improve the accuracy of medical image classification. Unfortunately, current research shows that federated learning faces the risk of privacy leakage. In this paper, we propose a privacy-preserving scheme FHDM. Specifically, we construct a local hybrid differential privacy algorithm (LHDP) against patients’ privacy leakage. This hybrid algorithm utilizes both Gaussian and Laplace differential privacy without enlarging the privacy budget. We prove that the algorithm applies to the model parameter. Moreover, we design loss optimization and global optimization strategies on the algorithm to achieve higher accuracy in medical image classification. Finally, we validate FHDM in terms of privacy-preserving and model accuracy on real datasets. Experiments show that FHDM effectively protects privacy and improves the average accuracy by 10.0% compared to adopting the LDP-based scheme with the same medical image dataset and privacy budget.
Haotian Chi, Shunrong Jiang, Xiaojiang Du, Mohsen Guizani
GLOBECOM5
2024 P²SimiDedup: Privacy-Preserving and Similarity-Based Deduplication Scheme for Fog-Assisted Vehicular Crowdsensing System
abstract
The rapid development of fog-assisted vehicular crowdsensing systems (FVCSs) enables real-time vehicular data sharing, but redundant and similar data in report results in unnecessary costs. However, previous studies only focus on duplicate reports and neglect deduplication of similar data. Besides, transmitting crowdsensing data in Internet of Vehicles (IoV) exposes vulnerabilities to offline brute-force and fake report attacks. In this article, we present P2SimiDedup, a scheme for secure deduplication of similar crowdsensing reports. Specifically, we develop cryptographic primitives and introduce an improved generalized deduplication technique (GreedyGD) to achieve secure deduplication over similar crowdsensing data. Then, we construct a two-level deduplication framework that can perform secure and efficient similar-based deduplication at fog nodes and cloud server. Besides, P2SimiDedup can ensure that only data requesters can decrypt and recover crowdsensing data. The security analysis and evaluation results demonstrate that P2SimiDedup can achieve privacy-preserving deduplication for similar crowdsensing reports with moderate computational, communication, and storage costs.
Qiliang Zhang, Tom H. Luan, Yiliang Liu, Shunrong Jiang, Yong Zhou 0003
IEEE Internet Things J.5
2024 Vehicular Edge Computing Meets Cache: An Access Control Scheme With Fair Incentives for Privacy-Aware Content Delivery
abstract
Vehicular Edge Computing (VEC) integrates mobile edge computing with traditional vehicular networks, which shifts the majority of computation and storage workload of resource-constrained vehicles to the edge nodes. The high mobility of vehicles usually leads to frequent network changes and connection interruptions, making data sharing more challenging in such dynamic and unstable environments. To address this issue, cache-based content delivery is considered a promising solution for efficient data sharing in VEC. However, access control and fair incentive distribution in privacy-aware data sharing are rarely taken into account in prior VEC-oriented studies. In this paper, we propose RFIP-VEC, a Revocable access control scheme with Fair Incentive for Privacy-aware content delivery in VEC. Specifically, to enable anonymous authentication and conditional revocation, we construct a secure group signature scheme with formally proved security guarantees. Subsequently, based on our group signature scheme, we design a two-layer access control framework by employing proxy re-encryption. We also establish an evolutionary game theory model to analyze the effectiveness and fairness of the fair incentive in our scheme. Thus, our scheme can achieve flexible access control and fair incentive distribution with the assistance of edge nodes. Security analysis and experimental results demonstrate that the proposed scheme can achieve security goals with affordable cost in terms of network performance in VEC.
Shunrong Jiang, Guohuai Sang, Haiqin Wu, Yong Zhou 0003
IEEE Trans. Intell. Transp. Syst.1
2024 VP$^{2}$2-Match: Verifiable Privacy-Aware and Personalized Crowdsourcing Task Matching via Blockchain
abstract
Privacy-aware task allocation/matching has been an active research focus in crowdsourcing. However, existing studies focus on an honest-but-curious assumption and a single-attribute matching model. There is a lack of adequate attention paid to scheme designs against malicious behaviors and supporting user-side personalized task matching over multiple attributes. A few recent works employ blockchain and cryptographic techniques to decentralize the matching procedure with verifiable and privacy-preserving on-chain executions. However, they still bear expensive on-chain overhead. In this paper, we propose VP$^{2}$-Match, a blockchain-assisted (publicly) verifiable privacy-aware crowdsourcing task matching scheme with personalization. VP$^{2}$-Match extends symmetric hidden vector encryption for user-side expressive matching without compromising their privacy. It avoids costly on-chain matching by letting the blockchain only store evidence/proofs for public verifiability of the matching correctness and for enforcing fair interactions against misbehaviors. Specifically, we construct extended attribute sets and solve matching verification by an algorithmic reduction into subset verification with an accumulator for proof generation. Formal security proof and extensive comparison experiments on Ethereum demonstrate the provable security and better performance of VP$^{2}$-Match, respectively.
Haiqin Wu, Boris Düdder, Shunrong Jiang, Liangmin Wang 0001
IEEE Trans. Mob. Comput.3
2024 Privacy-Preserving and Fair Crowdsourcing Framework With Fine-Grained Reuse Based on Blockchain
abstract
Crowdsourcing has gained many developments and wide applications in our daily life. Traditional centralized crowdsourcing systems suffer from high management costs and low efficiency. The recent advance in the blockchain technology has enabled the construction of decentralized crowdsourcing systems, which can overcome the limitations of centralized systems and make crowdsourcing solution reuse possible. However, such systems also bring new security and privacy challenges. For instance, transactions on blockchain are publicly visible which can lead to privacy leakage of crowdsourcing users. Moreover, unfair exchange is a critical issue on these platforms. In this paper, we propose a privacy-preserving and fair crowdsourcing framework with fine-grained reuse based on blockchain to meet the security requirements for decentralized crowdsourcing. Specifically, we construct one-address-only (OAO) authentication to ensure the uniqueness of the participant’s address in the crowdsourcing process. Additionally, We design a submit-then-open method with commitments to resist the “free-riding" and “false-reporting" attacks. Thus, fair exchange between entities can be guaranteed. To ensure data confidentiality and fine-grained solution item reuse, we employ pairing-based cryptography to generate an encryption key and ensure flexible authorization reuse. We also adopt stealth authorization techniques to ensure privacy-preserving access authorization during the reuse phase. Finally, security analysis and implementation results have shown that the proposed framework can effectively achieve privacy-preserving and fair crowdsourcing as well as fine-grained crowdsourcing reuse. Specifically, the gas consumption in the reuse phase is reduced by approximately 49% to 81% compared to the normal operation, which significantly improves the efficiency of blockchain applications.
Shunrong Jiang, Xiao Zhang 0047, Haiqin Wu, Yiliang Liu, Yong Zhou 0003
IEEE Trans. Netw. Serv. Manag.1
2023 DCAMM: Dynamic Curve-Based Automated Market Maker
abstract
Decentralized Exchanges (DEX) allow cryptocurrencies to trade autonomously with each other without involving any centralized financial intermediaries. Among these DEX models, Automated Market Maker (AMM) is most commonly used by major platforms like Uniswap and Curve. However, a typical AMM suffers three main challenges. First, arbitrage trading may cause AMM-based liquidity providers to lose liquidity in assets. Second, adversaries extract on a monthly basis over 10 million USD from AMM traders via sandwich attacks. Third, the volatility of asset prices in AMM may violate the fairness of trading. In this work, we propose a new AMM design, Dynamic Curve-based Automated Market Maker (DCAMM), which utilizes a price oracle with real-time market price feedback to automatically adjust the pool's asset price to match the market price. In DCAMM, there is no space for price manipulation, and traders' slippage losses are converted into equal gains for the liquidity pool. Thus, DCAMM provides the resistance to arbitrage trading and sandwich attacks. Moreover, DCAMM provides a more stable asset price through a strict price adjustment, benefiting traders and safeguarding trading fairness.
Shunrong Jiang, Fengjiao Li, Haijun Geng, Haotian Chi
GLOBECOM1
2023 EAKM: Efficient Conditional Privacy-Preserving Authentication Scheme with On-Chain Key Management in VANETs
abstract
Conditional privacy-preserving authentication can provide anonymity and traceability to Vehicular Ad-Hoc Networks (VANETs), which protects users' privacy while resisting malicious users and false messages. However, existing schemes suffer from various disadvantages, such as unavailable batch verification, unrenewable user public keys/certificates, and untimely revocation. In this work, we design an efficient conditional privacy-preserving authentication scheme with the on-chain key management (EAKM) for VANETs. To achieve lightweight authentication, we design an efficient Signature of Knowledge (SoK) and a batch verification algorithm. Moreover, we use the hash chain technology to update users' anonymous public keys. In addition, based on the blockchain technology and smart contract, we could manage users' anonymous public keys efficiently and transparently. Security analysis and simulation results show that EAKM ensures conditional privacy with less authentication overhead.
Shunrong Jiang, Guohuai Sang, Xuedan Jia, Fengjiao Li, Haotian Chi
GLOBECOM1
2023 PACM: Privacy-Preserving Authentication Scheme With on-Chain Certificate Management for VANETs
abstract
Privacy-preserving authentication is designed to protect vehicular ad-hoc networks (VANETs) from illegitimate users and fake messages while maintaining the privacy of legitimate users’ identities. However, existing authentication schemes have disadvantages such as non-transparent certificate issuance and revocation, high identity authentication and certificate revocation overhead. In this paper, we propose an efficient privacy-preserving authentication scheme with on-chain certificate management (PACM) in VANETs, where the service manager (SM) of each domain serves as a node of the blockchain to build a distributed system. Specifically, based on elliptic curve cryptography (ECC) and exclusive-OR operations, we achieve secure and lightweight mutual authentication between vehicles and roadside units (RSUs) by regularly updated pseudonyms. Then, we adopt the blockchain to record the issuance and revocation of all certificates, which makes SM’s activities transparent. Moreover, we introduce the counting garbled bloom filter (CGBF) to enable fast query and revocation of certificates. Besides, we design a non-forgeable and non-repudiable billing mechanism based on the hash chain technology. Security analysis and experimental results show that PACM achieves stronger security with less overhead.
Guohuai Sang, Yiliang Liu, Haiqin Wu, Yong Zhou 0003, Shunrong Jiang
IEEE Trans. Netw. Serv. Manag.6
2023 Query Integrity Meets Blockchain: A Privacy-Preserving Verification Framework for Outsourced Encrypted Data
abstract
Cloud outsourcing provides flexible storage and computation services for data users in a low cost, but it brings many security threats as the cloud server may not be fully trusted. Previous secure outsourcing solutions mostly assume that the server is honest-but-curious while the adversary model of a malicious server that may return incorrect results is rarely explored. Moreover, with the increasing popularity of verifiable computations, existing verification schemes are yet not efficient and cannot cater to different scenarios in practice. In this paper, we propose a blockchain-based verifiable search framework in the adversarial cloud outsourcing context. When outsourcing the encrypted data to the cloud or Interplanetary File System (IPFS), we also store the encrypted data index in a decentralized blockchain (i.e., Ethereum in this paper) which is public and cannot be modified. Once a user is authorized, he/she can flexibly obtain the query results and efficiently check the query integrity via the pre-deployed smart contract, without the need of the data owner being online. Moreover, for user's privacy protection, we construct a stealth authorization scheme to deliver the access authorization without any identity disclosure. Finally, theoretical analysis and performance evaluation validate the security and efficiency of our proposed framework.
Shunrong Jiang, Jianqing Liu, Yiliang Liu, Liangmin Wang 0001, Yong Zhou 0003
IEEE Trans. Serv. Comput.1
2022 FVC-Dedup: A Secure Report Deduplication Scheme in a Fog-Assisted Vehicular Crowdsensing System
abstract
It is observed that modern vehicles are becoming more and more powerful in computing, communications, and storage capacity. By interacting with other vehicles or with local infrastructures (i.e., fog) such as road-side units, vehicles and fog devices can collaboratively provide services like crowdsensing in an efficient and secure way. Unfortunately, it is hard to develop a secure and privacy-preserving crowdsensing report deduplication mechanism in such a system. In this article, we propose a scheme FVC-Dedup to address this challenge. Specifically, we develop cryptographic primitives to realize secure task allocation and guarantee the confidentiality of crowdsensing reports. During the report submission, we improve the message-lock encryption (MLE) scheme to realize privacy-preserving report deduplication and resist the fake duplicate attacks. Besides, we construct a novel signature scheme to achieve efficient signature aggregation and record the contributions of each participant fairly without knowing the crowdsensing data. The security analysis and performance evaluation demonstrate that FVC-Dedup can achieve secure and privacy-preserving report deduplication with moderate computing and communication overhead.
Shunrong Jiang, Jianqing Liu, Yong Zhou 0003, Yuguang Fang
IEEE Trans. Dependable Secur. Comput.1
2022 Privacy-Preserving Scheme With Account-Mapping and Noise-Adding for Energy Trading Based on Consortium Blockchain
abstract
The maturity in information technology and new energy technologies enables participants to generate, buy, and sell energy in energy trading systems. Although applying blockchain technology to energy trading has solved some drawbacks in traditional centralized energy systems, the openness and transparency characteristics make the trading records stored on the blockchain vulnerable to data-mining attacks that may cause indispensable privacy leakage. Due to high efficiency and low overhead, noise-addition is an appropriate solution for privacy preservation. Nonetheless, recent research on noise-addition needs to generate massive accounts, which brings a certain amount of waste and inconvenience for later regulation and management. To avoid the aforementioned issues, this paper proposes a consortium blockchain-enabled scheme to ensure the privacy of data stored on the blockchain and resist linking attacks initiated by data mining algorithms. Our scheme utilizes a dynamic partition algorithm to leverage an account mapping algorithm and a virtual token algorithm. Specifically, the account mapping algorithm utilizes a dynamic account allocation method to hide the trading distribution of active users. Furthermore, the virtual token algorithm applies Laplace noise to hide the actual energy consumption of inactive users and curb excessive accounts generation. Finally, we formally demonstrate the privacy and effectiveness of our proposed scheme in security analysis and experiment evaluations.
Shunrong Jiang, Yiliang Liu, Tao Jiang 0017, Yong Zhou 0003
IEEE Trans. Netw. Serv. Manag.2
2020 Secure and Privacy-preserving Energy Trading Scheme based on Blockchain
abstract
The large-scale integration of distributed energy resources has resulted in surgical changes in energy trading systems. Traditional centralized trading systems suffer from high management cost and low efficiency. The recent advance of blockchain technology has enabled the invention of distributed energy trading systems, which can overcome the limitations of centralized trading systems. However, the distributed energy trading systems also bring new security and privacy challenges. For instance, transactions on blockchain are publicly visible which can lead to privacy leakage of trading information. Moreover, user privacy can also be leaked during verification of the aggregated energy trading result. In this paper, we propose a privacy-preserving energy trading scheme based on blockchain to meet the security requirements for distributed energy trading. We adopt a stealth transmission approach based on blockchain to ensure data privacy and break the linkage between consumers and providers in the energy trading process. We also use the non-interactive zero-knowledge proof technology to achieve privacy-preserving and trustworthy trading result verification. Security analysis and evaluation results have demonstrated that the proposed scheme can effectively protect the data privacy for distributed energy trading systems.
Shunrong Jiang, Hao Yue 0001, Yong Zhou 0003
GLOBECOM1
2020 Vehicular Edge Computing Meets Cache: An Access Control Scheme for Content Delivery
abstract
Vehicular Edge Computing (VEC) is an integration of Mobile Edge Computing with traditional vehicular networks, which aims to shift computing, communication, and storage resources to the edge of networks and is more close to vehicles. Due to the high mobility of vehicles, connection interruption and network changes may frequently occur. To tackle this issue, cache-based content delivery is regarded as a promising solution to achieve efficient data sharing in VEC. However, privacy-preserving access control and fair incentive distribution are rarely taken into account in prior VEC-oriented studies. In this paper, we propose an efficient and secure access control scheme for providing cache-based content delivery in VEC. Specifically, we construct two layer access control to enable flexible access control and fair incentive distribution with the assistance of edge nodes. Moreover, we construct a group signature-based scheme to achieve anonymous authentication and conditional revocation. The performance analysis shows that our secure scheme has an acceptable effect on network performance.
Shunrong Jiang, Jianqing Liu, Longxia Huang, Haiqin Wu, Yong Zhou 0003
ICC1
2020 Secure and Efficient Cloud Data Deduplication with Ownership Management
abstract
Data deduplication has been widely used in cloud storage to reduce storage space and communication overhead by eliminating redundant data and storing only one copy for them. In order to achieve secure data deduplication, the convergent encryption scheme and many of its variants are proposed. However, most of these schemes do not consider or cannot address the efficiently dynamic ownership changes and the secure Proof-of-Ownership (PoW), simultaneously. In this paper, we propose a secure data deduplication scheme with efficient PoW process for dynamic ownership management. Specially, our scheme supports both cross-user file-level and inside-user block-level data deduplication. During the file-level deduplication, we construct a new PoW scheme to ensure the tag consistency and achieve the mutual ownership verification. Moreover, we design a lazy update strategy to achieve efficient ownership management. For inside-user block-level deduplication, the user-aided key is used to realize convergent key management and reduce the key storage space. Finally, the security and performance analysis demonstrate that our scheme can ensure data confidentiality and tag consistency, and it is efficient in data ownership management.
Shunrong Jiang, Tao Jiang 0017, Liangmin Wang 0001
IEEE Trans. Serv. Comput.1
2019 Patients-Controlled Secure and Privacy-Preserving EHRs Sharing Scheme Based on Consortium Blockchain
abstract
The large-scale deployment of eHealth systems has brought deep impact on human society. However, the centralized Electronic health records (EHRs) outsourcing system faces some critical security and privacy issues, which have raised wide concerns in both academia and industry. Moreover, the patients lose control of their health data. There is a need to construct a decentralized and secure EHRs with more flexible control by patients themselves instead of the third party. Fortunately, we observe that the characteristics of blockchain technology such as decentralization, immutability, and auditability perfectly match these aforementioned requirements. Specifically, to satisfy our application requirements, we build a consortium blockchain (PESchain) which is maintained by a set of medical institutions. The EHRs of patients are encrypted and stored in the medical institutions by local cloud while the corresponding hash values are stored on PESchain. Moreover, to enable privacy-preserving EHRs sharing, we construct a stealth authorization scheme to achieve access authorization delivery on the blockchain. Besides, we pack the transactions according to different types to guarantee efficient block deletion. The security analysis and performance evaluation show that PESchain is secure and practical for EHRs sharing.
Shunrong Jiang, Haiqin Wu, Liangmin Wang 0001
GLOBECOM1
2019 Verifiable Search Meets Blockchain: A Privacy-Preserving Framework for Outsourced Encrypted Data
abstract
Outsourcing storage and computation to clouds is popular but also raises security concerns. Most existing solutions mainly focus on an honest-but-curious cloud server, while security designs against a malicious server have not drawn enough attention. Although there are a few works addressing the issue of verifiable designs that enable the data owner to verify the integrity of search results. Unfortunately, these verification schemes are not efficient and or applicable from one scenario to another. Motivated by this, in this paper, we propose a publicly verifiable search framework for outsourced encrypted data based on blockchain. In our framework, we store the encrypted index in a decentralized blockchain (Ethereum) while outsourcing the corresponding encrypted data to the cloud or Interplanetary File System (IPFS). Thus, once a user is authorized, he/she can get the query results and check the query integrity efficiently by the designed smart contract anytime without data owner being online. Besides, to guarantee the privacy of the data user in the Ethereum, we construct a stealth authorization scheme to achieve access authorization delivery. The security analysis and performance evaluation show that the proposed scheme is secure and practical for verification of encrypted data.
Shunrong Jiang, Jianqing Liu, Liangmin Wang 0001, Seong-Moo Yoo
ICC1
2019 Multi-hop interpersonal trust assessment in vehicular ad-hoc networks using three-valued subjective logic
abstract
Future vehicular networks need multi‐hop trusted information among car manoeuvres as a solution to the persistent problem of road safety, and news sharing. However, malicious users in vehicular networks can also disseminate fake information among each other. Traditional public key infrastructure is not an efficient solution for recognising these malicious users, as they all have authorised entities. To cope with this problem, this study highlights novel idea, i.e. three‐valued subjective logic (3VSL) as a trust model for multi‐hop trust assessment among users in vehicular ad‐hoc network (VANET). Trust among vehicle users is represented in the form of opinion derived from 3VSL and updated frequently due to vehicles random movement on the road. To support the authors’ proposed scheme, this study contains two parts in simulation, i.e. numerical and experimental analyses. Numerical analysis shows that 3VSL gives accurate trust assessment even with a bridge or random network topology, which is ignored previously by edge splitting. In the experimental part, we extend widely accepted ad‐hoc on‐demand distance vector routing protocol by directly applying trust fields to the routing table. The simulation experiment shows that their scheme achieves better performance in term of throughput and latencies in low mobility VANET scenario.
Muhammad Sohail 0001, Liangmin Wang 0001, Shunrong Jiang, Samar Zaineldeen, Rana Umair Ashraf
IET Inf. Secur.3
2019 A hierarchical mobility management scheme based on software defined networking
Xing Yin, Liangmin Wang 0001, Shunrong Jiang
Peer-to-Peer Netw. Appl.3
2019 Publicly Verifiable Boolean Query Over Outsourced Encrypted Data
abstract
Outsourcing storage and computation to the cloud has become a common practice for businesses and individuals. As the cloud is semi-trusted or susceptible to attacks, many researches suggest that the outsourced data should be encrypted and then retrieved by using searchable symmetric encryption (SSE) schemes. Since the cloud is not fully trusted, we doubt whether it would always process queries correctly or not. Therefore, there is a need for users to verify their query results. Motivated by this, in this paper, we propose a publicly verifiable dynamic searchable symmetric encryption scheme based on the accumulation tree. We first construct an accumulation tree based on encrypted data and then outsource both of them to the cloud. Next, during the search operation, the cloud generates the corresponding proof according to the query result by mapping Boolean query operations to set operations, while keeping privacy preservation and achieving the verification requirements: freshness, authenticity, and completeness. Finally, we extend our scheme by dividing the accumulation tree into different small accumulation trees to make our scheme scalable. The security analysis and performance evaluation show that the proposed scheme is secure and practical.
Shunrong Jiang, Xiaoyan Zhu 0005, Linke Guo, Jianqing Liu
IEEE Trans. Cloud Comput.1
2018 Secure and Privacy-Preserving Report De-duplication in the Fog-Based Vehicular Crowdsensing System
abstract
Nowadays, vehicles are powerful enough to carry communications, computing and storage capabilities. By interacting with each other and with local (i.e., fog) infrastructures like road-side units, a cohort of vehicles and fog devices could collaboratively provide services like crowdsensing in an unprecedentedly secure and efficient way. However, it has been widely recognized as a challenging work in the vehicular system to develop a secure and efficient sensing task allocation and data de-duplication mechanism. In this paper, we attempt to develop a scheme to address this challenge. Specifically, we use the Elliptic Curves Cryptography (ECC) algorithm to realize secure allocation of location-dependent tasks. During the report submission phase, we adopt the improved message-lock encryption to realize privacy-preserving data de-duplication and to resist the duplicate-faking attacks. Besides, we present a novel signature scheme that can efficiently record the contributions of each vehicle. The security analysis and performance evaluation demonstrate that the proposed scheme can achieve secure and privacy-preserving report de-duplication with moderate computation and communication overhead.
Shunrong Jiang, Jianqing Liu, Mengjie Duan, Liangmin Wang 0001, Yuguang Fang
GLOBECOM1
2018 A Secure Data Forwarding Scheme in Vehicular Named Data Networking
abstract
In vehicular ad hoc networks (VANETs), vehicles' mobility and urban obstacles may cause frequent communication disconnections and sudden network changes. As a result, the traditional IP-based node-to-node content delivery mechanism does not adapt well to such changes in VANETs. To solve this problem, in this paper, we study the Named Data Networking (NDN) architecture to support efficient and secure data forwarding in urban VANETs. To meet security requirements, we adopt the encryption-based name obfuscation to achieve Interest-based access control. Moreover, the revocation of illegal vehicles and the updated operation are addressed by proxy re-encryption method, which saves the main communication overhead during the process. Finally, we design an incentive scheme to guarantee the utility of NDN in VANETs. The security analysis shows that the proposed secure scheme can satisfy security requirements of the data forwarding in VANETs. The performance analysis indicates that the overhead caused by the proposed secure scheme is low and acceptable.
Shunrong Jiang, Jianqing Liu, Liangmin Wang 0001, Yuguang Fang
GLOBECOM1
2018 Secure Top-k Preference Query for Location-based Services in Crowd-outsourcing Environments
abstract
This paper considers a practical crowd-outsourcing system model for location-based services which has become increasingly popular due to the rapid proliferation of location-aware mobile devices. In our system, multiple data owners (DOs) outsource their small number of points of interests (POIs) to the location-based service provider (LBSP), then LBSP manages these POIs datasets and allows users to share information and perform top-k queries according to their own preferences. One crucial problem in this system is how to deal with the untrusted LBSP, who may return fake or incorrect query results to users for certain motives. However, the traditional top-k query and verification schemes, where only an individual DO and a single query attribute are considered, cannot be efficiently applied to our system, as users have distinct query preferences and the query may involve multiple DOs. In this paper, we design a dominant authentication graph DAUG) to process the multi-attribute data on multiple datasets efficiently, and two schemes are proposed for users to verify the integrity of the query result based on DAUG. Finally, theoretical analysis and simulation results show our superiority to the previous scheme in terms of effectiveness and efficiency.
Haiqin Wu, Liangmin Wang 0001, Shunrong Jiang
Comput. J.3
2018 Toward Privacy-Preserving Symptoms Matching in SDN-Based Mobile Healthcare Social Networks
abstract
Mobile healthcare social networks (MHSNs) have arisen as a very promising brandnew healthcare system, which will greatly improve the quality of life. Moreover, with the help of software defined networking (SDN) paradigm, it can enhance the user experience. To achieve personal health information sharing and the access control among parities, a similar symptoms matching process should be executed before that. However, the matching process requires users to exchange symptoms information, conflicting with the ever-increasing privacy concerns on protecting private symptoms from strangers. To realize privacy-preserving symptoms matching, in this paper, we design two blind signature-based symptom matching schemes in SDN-based MHSNs, which can achieve the coarse-grained symptom matching and fine-grained symptom matching, respectively. Moreover, our schemes do not relay on any trusted third party. Security analysis and detailed simulations show that our proposed schemes can realize efficient privacy-preserving symptom matching. Finally, we do comprehensive experimental evaluation on real-world smartphones to demonstrate the practicality of our proposed schemes.
Shunrong Jiang, Mengjie Duan, Liangmin Wang 0001
IEEE Internet Things J.1
2017 An Efficient and Secure Authentication Scheme for In-vehicle Networks in Connected Vehicle
Mengjie Duan, Shunrong Jiang, Liangmin Wang 0001
MSN2
2016 An Efficient Anonymous Batch Authentication Scheme Based on HMAC for VANETs
abstract
In vehicular ad hoc networks (VANETs), when a vehicle receives a message, the certificate revocation list (CRL) checking process will operate before certificate and signature verification. However, large communication sources, storage space, and checking time are needed for CRLs that cause the privacy disclosure issue as well. To address these issues, in this paper, we propose an efficient anonymous batch authentication scheme (ABAH) to replace the CRL checking process by calculating the hash message authentication code (HMAC). In our scheme, we first divide the precinct into several domains, in which road-side units (RSUs) manage vehicles in a localized manner. Then, we adopt pseudonyms to achieve privacy-preserving and realize batch authentication by using an identity-based signature (IBS). Finally, we use HMAC to avoid the time-consuming CRL checking and to ensure the integrity of messages that may get loss in previous batch authentication. The security and performance analysis are carried out to demonstrate that ABAH is more efficient in terms of verification delay than the conventional authentication methods employing CRLs. Meanwhile, our solution can keep conditional privacy in VANETs.
Shunrong Jiang, Xiaoyan Zhu 0005, Liangmin Wang 0001
IEEE Trans. Intell. Transp. Syst.1
2015 Publicly Verifiable Boolean Query over Outsourced Encrypted Data
abstract
Outsourcing storage and computation to the cloud has become a common practice for businesses and individuals. As the cloud is semi-trusted or susceptible to attacks, many researches suggest that the outsourced data should be encrypted and then retrieved by using searchable symmetric encryption (SSE) schemes. Since the cloud is not fully trusted, we doubt whether it would always process queries correctly or not. Therefore, there is a need for users to verify their query results. Motivated by this, in this paper, we propose a publicly verifiable dynamic searchable symmetric encryption scheme based on the accumulation tree. We first construct an accumulation tree based on encrypted data and then outsource both of them to the cloud. Next, during the search operation, the cloud generates the corresponding proof according to the query result by mapping Boolean query operations to set operations while keeping privacy-preservation and achieving the verification requirements: authenticity, freshness, and completeness. The security analysis and performance evaluation show that the proposed scheme is privacy-preserving and practical.
Shunrong Jiang, Xiaoyan Zhu 0005, Linke Guo, Jianqing Liu
GLOBECOM1
2015 Verification of Boolean Queries over Outsourced Encrypted Data Based on Counting Bloom Filter
abstract
Recent years witness the rapid development of cloud computing and more and more data owners outsource their data to the cloud. To eliminate the disclosure of authorized data users' privacy in cloud services (e.g., cloud storage or cloud-assisted computing)-since the cloud providers cannot be fully trustworthy-several previous works have proposed considerable privacy-preserving schemes by exploiting searchable encryption. However, owing to its feature of untrusty, issue arises on how data users can verify whether the cloud has faithfully executed the search operations or not. Motivated by this question, in this paper, we propose a searchable and verifiable query scheme over encrypted data based on Counting Bloom Filter (CBF). Specifically, we deploy counting bloom filters to generate proofs for data users' queries in the private cloud; using the consistence between algebra operations on counting bloom filters and on data sets, we can verify the integrity of search result. The security analysis and performance evaluation show that the proposed scheme is privacy-preserving and is feasible to implement.
Xiaoyan Zhu 0005, Ripei Hao, Shunrong Jiang, Haotian Chi, Hongning Li
GLOBECOM3
2015 Efficient private matching based on blind signature for proximity-based mobile social networks
abstract
Proximity-based mobile social networks (PMSNs) are becoming increasingly popular due to the explosive growth of mobile devices in recent years, where a user can find a best matching friend within a nearby proximity through profile matching. However, the matching process calls for the exchange of users' personal information, which conflicts with their growing privacy concerns on revealing their profiles to strangers. Although a few methods have been proposed to achieve privacy-preserving friend discovery, most of them introduce tremendous communication overhead to the system so that they are not practical for resource-limited mobile devices. In this paper, we propose a private matching scheme based on blind signature for PMSNs, which can achieve a fine-grained matching and preferably protect users' privacy without relying on any Trusted Third Party (TTP). Moreover, our scheme can significantly reduce the communication overhead even when working as a group matching mode. Security analysis and detailed simulations show that the proposed scheme can achieve efficient privacy-preserving friend discovery.
Shunrong Jiang, Xiaoyan Zhu 0005, Linke Guo, Ripei Hao
ICC1
2015 Lightweight and privacy-preserving agent data transmission for mobile Healthcare
abstract
With the pervasiveness of smartphones and the advance of wireless body sensor networks (WBSNs), mobile healthcare (m-healthcare) has attracted considerable interest recently. In m-Healthcare, users' smartphones serve as bridges connecting their WBSNs and the healthcare center (HCC), i.e., send users' personal health information (PHI) collected by WBSNs to the HCC and receive the feedback. However, users' smartphones are not always available (e.g., left at home or out of power), resulting in an unexpected interruption of medical services sometimes, which are not considered in most existing schemes for m-healthcare. In this paper, we propose a lightweight and privacy-preserving agent data transmission scheme for m-healthcare in opportunistic social networks on condition that the smartphone is not available. By using the proposed protocol, we can provide uninterrupted healthcare while keeping the user's identity and PHI private during the agent transmitting of PHI. Security and performance analysis show that the proposed scheme can realize privacy-preservation and achieve secure end-to-end communication for m-healthcare, and is suitable for resource-limited WBSNs.
Shunrong Jiang, Xiaoyan Zhu 0005, Ripei Hao, Haotian Chi, Hui Li 0006, Liangmin Wang 0001
ICC1
2014 Two-party and multi-party private matching for proximity-based mobile social networks
abstract
Proximity-based mobile social networks (PMSNs) are a novel type of social networks, where mobile users can choose potential friends in vicinity by comparing the similarity degree between their private attributes and make new connections through the WiFi/Bluetooth interfaces on their mobile devices. Since users' personal attributes usually contain some sensitive information, users may have increasing privacy concerns and do not want to reveal their attributes to others in the process of friend discovery. In this paper, we first propose a two-party private matching algorithm, which achieves a fine-grained match and protects users' privacy preferably without reliance on any Trusted Third Party (TTP). Based on the two-party protocol, we then present a multi-party matching protocol, where a responder who satisfies the pre-defined threshold can match with a group of users without breaching their privacy. By the detailed analysis and simulations, we evaluate our two matching schemes in terms of security, communication overhead and computation overhead, which show a better performance than other related protocols.
Xiaoyan Zhu 0005, Zengbao Chen, Haotian Chi, Shunrong Jiang
ICC5
2014 Using dynamic pseudo-IDs to protect privacy in location-based services
abstract
Location-based services (LBSs) are attracting more and more attentions with the increasing popularity of mobile devices and online social networking. In LBSs, users can conveniently obtain their interested information by sending queries to the LBS server. However, users' queries include their identities, locations, interests, etc, which may result in the leakage of users' trajectory and other sensitive information. Although the existing obfuscation and location anonymization techniques along with a long-term pseudonym can protect users' location privacy to some extent, users' real identities and moving trajectories can still be deduced through long-term observation and side information aided inference attacks. To address these problems, we propose a dynamic pseudo-ID system, where unlinkable pseudo-IDs are used by users to completely hide their identities in the queries, in order to break the link between users' identities and their locations. Moreover, we employ certificates to ensure the verifiability and traceability of the dynamic pseudo-IDs. Security analysis and evaluation results show that the proposed scheme can enhance user' privacy and is feasible to implement into mobile devices.
Xiaoyan Zhu 0005, Haotian Chi, Shunrong Jiang, Xiaosan Lei, Hui Li 0006
ICC3
2014 Efficient Weight-based Private Matching for proximity-based mobile social networks
abstract
Proximity-based mobile social networks (PMSNs) are becoming increasingly popular in recent years with the explosive growth of mobile devices, where a user can find a best matching friend in vicinity through profile matching. However, the matching process calls for the publication of users' personal information, which conflicts with users' growing privacy concerns about revealing their profiles to strangers. To achieve privacy-preserving friend discovery, many schemes are proposed based on traditional cryptographic methods, such as homomorphic and commutative encryption, which inevitably introduce tremendous overhead to the system and are not practical for the resource-limited mobile devices. In this paper, we propose an Efficient Weight-based Private Matching (EWPM) protocol, which provides a realistic matching approach considering both the number of common interests and the corresponding weights on them. In EWPM, we utilize the Confusion Matrix Transformation (CMT) algorithm to achieve a secure and efficient matching. Security analysis and detailed simulations show that our proposed scheme can realize privacy-preserving friend discovery with higher efficiency.
Xiaoyan Zhu 0005, Shunrong Jiang, Zengbao Chen, Hui Li 0006
ICC3
2013 A conditional privacy scheme based on anonymized batch authentication in Vehicular Ad Hoc Networks
abstract
Addressing security and privacy issues is a prerequisite for market-ready Vehicular Ad Hoc Networks. In this paper, an anonymous batch authentication scheme is proposed to authenticate multiple requests sent from different vehicles at the same time. The scheme achieves privacy-preserving by pseudonyms, ensures the backward privacy of the revoked vehicles by hash chain, and realize the batch authentication by using an identity-based signature (IBS). To avoid the communication overhead caused by broadcasting the Certificate Revocation List (CRL) and the privacy disclosure issue of the revocation vehicles, we revoke the illegal vehicles through calculating Hash Message Authentication Code (HMAC) by using the group key. In addition, integrity of the batch messages is ensured and efficient batch authentication is achieved. The analysis shows that our scheme has a better performance than the current batch authentication schemes on authentication delay and revocation overhead. The generated group key and pair key during the authenticated process can be used for value-added service, as the realization of HMAC doesn't require additional overhead.
Shunrong Jiang, Xiaoyan Zhu 0005, Liangmin Wang 0001
WCNC1